HomeSecuritySQL injection bypasses airport security checks

SQL injection bypasses airport security checks

Security researchers have discovered an SQL injection vulnerability in a key airline security system, allowing unauthorized individuals to potentially bypass airport security checks and gain access to aircraft cockpits.

See also: VMware Aria Automation flaw allows SQL Injection

Airport security SQL injection

Researchers Ian Carroll and Sam Curry discovered the SQL injection vulnerability in FlyCASS , a third-party web-based service that some airlines use to manage their Known Crewmember (KCM) program and Cockpit Access Security System (CASS) . KCM is a Transportation Security Administration (TSA) initiative that allows pilots and flight attendants to bypass security screening, and CASS allows authorized pilots to use jumpseats in cockpits when traveling.

The KCM system, operated by ARINC (a subsidiary of Collins Aerospace), verifies credentials through an online platform. The process involves scanning a KCM barcode or entering an employee number, then cross-checking it with the airline’s database to grant access without requiring a security check. Similarly, the CASS system verifies pilots for access to the cockpit when they need to travel or commute.

Researchers discovered that the FlyCASS login system was susceptible to SQL injection, a vulnerability that allows attackers to insert SQL statements to perform malicious database queries. By exploiting this flaw, they could log in as administrators at an airline and manipulate employee data within the system .

They added a virtual employee, “Test TestOnly,” and granted this account access to KCM and CASS, which essentially allowed them to “bypass security screening” and then access the cockpits of commercial aircraft.

See also: Fortra FileCatalyst Workflow: PoC exploit for SQLi vulnerability

Realizing the seriousness of the issue, the researchers immediately initiated a disclosure process, contacting the Department of Homeland Security (DHS) on April 23, 2024.The researchers decided not to contact the FlyCASS website directly as it appeared to be run by a single person and they feared disclosure would alarm them.

SQL injection bypasses airport security checks

DHS responded, acknowledging the severity of the vulnerability and confirming that FlyCASS was disconnected from the KCM/CASS system on May 7, 2024, as a precautionary measure. The vulnerability was patched in FyCASS shortly thereafter. However, efforts to further coordinate a secure disclosure of the SQL injection vulnerability were met with resistance after DHS stopped responding to their emails.

The TSA press office also sent researchers a statement denying the impact of the vulnerability, claiming that the system’s audit process would prevent unauthorized access. After being notified by the researchers, the TSA also quietly removed information from its website that contradicted its statements.

Carroll said the flaw could have allowed more extensive security breaches, such as changing existing KCM member profiles to bypass any vetting processes for new members.

After the researchers' report was published, another researcher named Alesandro Ortiz discovered that FlyCASS appeared to have been attacked by the MedusaLocker in February 2024.

See also: Mallox Ransomware Detected in MS-SQL Honeypot Attack

SQL injection is one of the most common and dangerous attacks on databases. This process exploits vulnerabilities in applications that interact with databases, allowing malicious users to execute arbitrary SQL commands. SQL injection attacks can lead to data leakage, account compromise, and even complete control of the database if adequate security measures are not in place. To prevent this type of attack, it is important to use parameterized queries and other security techniques when developing applications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS